{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T15:41:28Z","timestamp":1759938088092,"version":"3.41.0"},"reference-count":44,"publisher":"Association for Computing Machinery (ACM)","issue":"SI","license":[{"start":{"date-parts":[[2018,4,25]],"date-time":"2018-04-25T00:00:00Z","timestamp":1524614400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGMIS Database"],"published-print":{"date-parts":[[2018,4,25]]},"abstract":"<jats:p>Research has investigated the role of numerous influences on individual information security behaviors, including protection motivation, deterrence, and various dispositional and environmental factors. Various theories have been applied to study these influences on security behaviors. One major research stream has looked at threat and coping appraisals by IT users. However, users' beliefs, attitudes, appraisals, and intentions are not static, and there has been little attention to how these factors interact over time. When users (directly or vicariously) experience a security threat, they tend to engage in improved security hygiene, but often only for a limited time. A major theory that can provide comprehensive and unified insights into the phenomenon of continuous secure behavior is the Theory of Process Memory which explains the role of prior experience effects and the underlying mechanisms of continuous behavior, including feedback mechanism, sequential updating mechanism, behavioral automaticity (habit), and reason-based action. The application of this theory to behavioral information security research can foster a deep understanding about how each cognitive mechanism can influence IT users' continuous secure behavior, and through which type of human memory each mechanism can act. This rich theory, which is well-established in cognitive psychology, can help behavioral information security scholars to rigorously investigate the very important, yet understudied, phenomenon of continuance secure behavior.<\/jats:p>","DOI":"10.1145\/3210530.3210534","type":"journal-article","created":{"date-parts":[[2018,4,27]],"date-time":"2018-04-27T16:00:21Z","timestamp":1524844821000},"page":"39-48","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Secure Behavior over Time"],"prefix":"10.1145","volume":"49","author":[{"given":"Ali","family":"Vedadi","sequence":"first","affiliation":[{"name":"Middle Tennessee State University, Murfreesboro, TN"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Merrill","family":"Warkentin","sequence":"additional","affiliation":[{"name":"Mississippi State University, Mississippi State, MS, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,4,25]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.2016.1243947"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017470.2017481"},{"key":"e_1_2_1_3_1","first-page":"89","volume-title":"K. W. Spence&J","author":"Atkinson R. C.","year":"1968"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3130515.3130519"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.2307\/3250921"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017219.2017224"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2013.36"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1086\/209112"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.5555\/2880309.2880312"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2015\/39.4.5"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017470.2017477"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1037\/0033-2909.92.1.111"},{"key":"e_1_2_1_13_1","first-page":"90","article-title":"Future directions for behavioral information security research","volume":"32","author":"Crossler R. E.","year":"2013","journal-title":"Computers&Security"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222310210"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2009.02.005"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/0010-0285(92)90002-J"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.10.007"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017470.2017478"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2015\/39.1.06"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1040.0326"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017410.2017417"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017356.2017361"},{"key":"e_1_2_1_23_1","first-page":"2","volume-title":"10th Annual Symposium on Information Assurance (ASIA'15)","author":"Mutchler L. A.","year":"2015"},{"key":"e_1_2_1_24_1","unstructured":"Myers D. G. (2004). Psychology (7th ed.). New York: Worth Publishers.  Myers D. G. (2004). Psychology (7th ed.). New York: Worth Publishers."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1177\/002224378001700405"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.5555\/2481626.2481629"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1037\/0033-2909.124.1.54"},{"key":"e_1_2_1_28_1","unstructured":"Ponemon (2017). Ponemon 2017 cost of data breach study. Retrieved September 1 2017 from https:\/\/www.ibm.com\/security\/data-breach\/  Ponemon (2017). Ponemon 2017 cost of data breach study. Retrieved September 1 2017 from https:\/\/www.ibm.com\/security\/data-breach\/"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2013\/37.4.09"},{"volume-title":"Retrieved","year":"2014","author":"Pw C.","key":"e_1_2_1_30_1"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1080\/00223980.1975.9915803"},{"key":"e_1_2_1_32_1","unstructured":"Rogers R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A Revised theory of protection motivation. In J. Cacioppo (Ed.) Social psychophysiology: A sourcebook (pp. 153--176). New York: Guilford Press.  Rogers R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A Revised theory of protection motivation. In J. Cacioppo (Ed.) Social psychophysiology: A sourcebook (pp. 153--176). New York: Guilford Press."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.01.002"},{"key":"e_1_2_1_34_1","unstructured":"Sharp. (2017). Employee IT behavior highlights GDPR compliance risk. Retrieved September 1 2017 from http:\/\/www.sharp.co.uk\/cpw\/rde\/xchg\/gb\/hs.xls\/- \/html\/employee-it-behaviour-highlights-gdprcompliance-risk.htm  Sharp. (2017). Employee IT behavior highlights GDPR compliance risk. Retrieved September 1 2017 from http:\/\/www.sharp.co.uk\/cpw\/rde\/xchg\/gb\/hs.xls\/- \/html\/employee-it-behaviour-highlights-gdprcompliance-risk.htm"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017470.2017475"},{"key":"e_1_2_1_36_1","unstructured":"Sophos (2017). Don't take the bait: How to spot phishing and social engineering scams. Retrieved September 1 2017 from https:\/\/www.sophos.com\/lp\/antiphishing\/prevention.aspx  Sophos (2017). Don't take the bait: How to spot phishing and social engineering scams. Retrieved September 1 2017 from https:\/\/www.sophos.com\/lp\/antiphishing\/prevention.aspx"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.im.2012.04.002"},{"key":"e_1_2_1_38_1","unstructured":"Vormetric. (2016). 2016 Vormetric data threat report. Retrieved September 1 2017 from https:\/\/ dtr.thalesecurity.com\/datathreat\/2016  Vormetric. (2016). 2016 Vormetric data threat report. Retrieved September 1 2017 from https:\/\/ dtr.thalesecurity.com\/datathreat\/2016"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.2307\/1251886"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2016.09.013"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1037\/0033-2909.121.3.331"},{"key":"e_1_2_1_42_1","unstructured":"Winn W. (2004). Cognitive perspectives in psychology. In D. Jonassen (Ed.) Handbook of research for educational communications and technology (pp. 79--112). Manwah NJ: Lawrence Erlbaum.  Winn W. (2004). Cognitive perspectives in psychology. In D. Jonassen (Ed.) Handbook of research for educational communications and technology (pp. 79--112). Manwah NJ: Lawrence Erlbaum."},{"key":"e_1_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Witte K. (1992). Putting the fear back into fear appeals: the extended parallel process model.  Witte K. (1992). Putting the fear back into fear appeals: the extended parallel process model.","DOI":"10.1080\/03637759209376276"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1080\/03637759409376328"}],"container-title":["ACM SIGMIS Database: the DATABASE for Advances in Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3210530.3210534","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3210530.3210534","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:13:13Z","timestamp":1750212793000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3210530.3210534"}},"subtitle":["Perspectives from the Theory of Process Memory"],"short-title":[],"issued":{"date-parts":[[2018,4,25]]},"references-count":44,"journal-issue":{"issue":"SI","published-print":{"date-parts":[[2018,4,25]]}},"alternative-id":["10.1145\/3210530.3210534"],"URL":"https:\/\/doi.org\/10.1145\/3210530.3210534","relation":{},"ISSN":["0095-0033","1532-0936"],"issn-type":[{"type":"print","value":"0095-0033"},{"type":"electronic","value":"1532-0936"}],"subject":[],"published":{"date-parts":[[2018,4,25]]},"assertion":[{"value":"2018-04-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}